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1.Refer to the exhibit. 


FortiGate-VM64-AWS # diagnose debug enable 


FortiGate-VM64-AWS # diagnose debug application awsd -1 
Debug messages will be on for 24 minutes. 


FortiGate-VM64-ANS # awsd sdn connector AWS Lab prepare to update 

awsd sdn connector AWS Lab start updating 

aws curl response err, 401 

<?xml version="1.8" encoding="UTF-8"7> 
<Response><Errors><Error><Code>AuthFailure</Code><Message>AWS was not able to validate 
the provided access credentials</Message></Error></Errors><RequestID>b3c88dfe-8 
97d-4367 -b839-ece48519f 1b8</Request ID></Response> 

aws access/secret key invalid 


awsd sdn connector AWS Lab failed to get instance list 
awsd reap child pid: 14257 

sdn AWS Lab firewall addr change 

awsd sdn connector AWS Lab prepare to update 


RS 
An administrator configured a FortiGate device to connect ome AWS API to retrieve 
resource values from the AWS console to create dynamig*objects for the 
FortiGatepolicies. The administrator is unable to retrieve AWS dynamic objects on 
FortiGate. ge 
Which three reasons can explain btw? (Choose dhree.) 
A. AWS was not able to validate credentials provided by the AWS Lab SON 
connector. oo” 
B. The AWS Lab SON connector failed to connect on port 401. 
C. The AWS Lab SON connector failed to retrieve the instance list. 
D. The AWS API call is not supported on XML version |. O. 
E. The AWS Lab SON connecti is configured with an invalid AWS access or secret 
key L 
Answer: A,C,E M 


2. An administrate? has deployed an environment in AWS and is now trying to send 
outbound traffi® trom the web servers to the internet through FortiGate. The FortiGate 
policies are configured to allow all outbound traffic. however. the traffic is not reaching 
the FortiGate internal interface. 

Which two statements Can be the reasons for this behavior? (Choose two) 

A. FortiGate is not configured as a default gateway tor web servers. 

B. Internet Gateway (IGW) is not configured for VPC. 

C. AWS security groups are blocking the traffic. 

D. AWS source destination checks are enabled on the FortiGate internal interfaces. 
Answer: C,D 


3. Refer to the exhibit. 


Create Load Balancer Actions Y 


` 
@ Name . DNS nome State 
@ Labdeis LabELB-631db'5946e05 tec provisioning 
Description Listeners Monitoring imegrated services Tags 


Basic Configuration 


State 

Type 

Scheme 

IP address type 


VPC 
Availability Zones 


LabELB 
arrcaws elasticioadbalancing us-esst-2°3 15085256806 loadbe 


LabELB-63fdbf5946e051 ec. elb.us-east-2.amazonaws.com C 


(A Record) 
provisioning 
network 


intemet-facing 


DVS 

vpco-0e3cf7352402f8b4e [7 

subnet-0e499a1966afc870 s-east-2c 7 
iPv4 address: Assigned by AWS 

subnet-009c68be44SDd6'c6 peast-23 (7 


IPv4 address: Assigned by AWS 


A customer is using the AWS Elastic Load Balancer. 
Which two statements are correct about the Elastic LoadBalancer configuration? 


(Choose two.) 


A. The Amazon resource name is used to access the load balancer node and targets. 
B. The DNS name is used to access devices. 
C. The load balancer is configured to load balance traffic between devices in two 


AZS. 


D. The load balancer is configuredfor the internal traffic ofthe VPC 


Answer: B,C 


4. Refer to the exhibit. 


Faj 
F 192 168.0 076 


10.0.0.0/16 


we 

172.16.0.0/16 S 
Fa 

Which statement is correct about the VPC peering conneétions shown in the exhibit? 

A. You can associate VPC ID pcx-23232323 with VPGB to form a VPC peering 

connection between VPC B and VPC C. a? 

B. You cannot route packets directly from VPC B’to VPC C through VPC 

A. C. TO route packets directly from VPC B toVPC C through VPC A, you must add a 

route for network 192.168.0.0/16 in the VBE A routing table. 

D. You cannot create a VPC peering cgsinection between VPC B and VPC C to route 

packets directly. ¥ 


9 
Answer: B o^ 
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5. Refer to the exhibit. Š 
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CLI Console 


WSOOO7D6FB66 # config 


FGTAWSO0U0 /D6FB66 ({auto-scale 
config system auto-scale 


set status enable 


sync-interface "por tl 


master-ip 10.0.0.173 
callback=-url https://e0aj/ 


sksecret ENC iWAnJ29gG11GyJN3 


PGTAWSO007D6FB6¢ 


You have created an autoscale configuratie# using a FortiGate HA Cloud Formation 
template. You want to examine the autgscale FortiOS configuration to confirm that 
FortiGate autoscale is configured to $fnchronize primary and secondary devices. On 
one of the FortiGate devices, yoy kecute the command 

shown in the exhibit. X 

Which statement is correct about the output of the command? 

A. The device is the primary in the HA configuration. with the IP address 10.0.0.173. 
B. The device is the sesondary in the HA configuration, and the IP address Of the 
primary device is 10%6.0.173. 

C. The device is hte primary in the HA configuration and the IP address of the 
secondary deviée is10.0.0.173. 

D. The device is the secondary in the HA configuration. with the IP address 
10.0.0.173. 

Answer: B 


6. Which features are only available on FortiWeb when compared to Fortinet 
Managed Rules for AWS WAF? 

A. FortiWeb meets PCI 6.6 compliance. 

B. FortiWeb can scan web application vulnerabilities. 

C. FortiWeb provides a WAF subscription (FortiGuard) option. 


D. FortiWeb provides web application attack signatures. 
Answer: B 


7. Which three Fortinet products are available in Amazon Web Services in both on- 
demand and bring your own license (BYOL) formats? (Choose three.) 

A. FortiGate 

B. FortiWeb 

C. FortiADC 

D. FortiSIEM 

E. FortisOAR 

Answer: A,B,C 


wv 

8. You connected to the AWS Management Console at 10:00 Aha verified that 
there are two FortiGate VMS running, You receive a call from auser reporting about a 
temporary slow Internet connection that lasted only a few mifiutes. When you go back 
to the AWS portal. you notice there are now two additiongt FortiGate VMS that you 
did not create. Later that day, the number of VMS retas to two without your 
intervention. A similar situation occurs several timgs*during the week. 
What is the most likely reason for this to happen? 
A. The VMS are in an availability group with dynamic membership. 
B. Autoscaling is configured to act as desorbed in the scenario. 
C. The user ran a script to create the exta VMS to get faster connectivity. 
D. The AWS portal is not refreshed gtomatically. and another administrator is 
creating and removing the VMS asheeded. 
Answer: B X 
Ci 

X 
9. Your company deplefed a FortiSandb0OX for AWS. 
Which statement is 6Orrect about FortiSandbox for AWS? 
A. FortiSandbox {er AWS does not need more resources because it performs only 
management aid analysis tasks. 
B. The FortiSandbox manager is installed on AWS platform and analyzes the results 
of the sandboxing process received from on-premises Windows instances. 
C. FortiSandbox for AWS comes as hybrid solution. The FortiSandob0X manager is 
installed on-premises and analyzes the results Of the sandboxing process received 
from AWS EC2 instances 
D. FortiSandbox deploys new EC2 instances with the custom Windows and Linux 
VMS, then it sends malware, runs it, and captures the results for analysis. 
Answer: A 


10. As part of the security plan you have been tasked with deploying a FortiGate in 


AWS. 


Which two are the security responsibility of the customer in a cloud environment? 


(Choose two.) 

A. Virtualization platform 
B. Traffic encryption 

C. User management 

D. Storage infrastructure 
Answer: B,C 
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